access only particular website through RADIUS

2007-08-26 Thread zamshed
dear Friends. I am a very new user of RADIUS. how can I configure this RADIUS for a particular USER,such as when that USER login with RADIUS,then that user only get PERMIT to access a fixed WEBSITE only,the rest others will b BLOCKED for that particular USER. Can I do that with this RADIUS

Re: access only particular website through RADIUS

2007-08-26 Thread liran tal
Others may correct me but I believe that this is not the role of the RADIUS server. To actually do this kind of filtering you need to use other technologies such as proxies or captive portal (see chillispot). Regards, Liran. On 8/26/07, zamshed [EMAIL PROTECTED] wrote: dear Friends. I am a

Re: access only particular website through RADIUS

2007-08-26 Thread Arran Cudbard-Bell
liran tal wrote: Others may correct me but I believe that this is not the role of the RADIUS server. To actually do this kind of filtering you need to use other technologies such as proxies or captive portal (see chillispot). Yep for the most part your correct. However, some specific NAS

Re: 13 LDAP queries for one authorize!

2007-08-26 Thread Phil Mayers
On Sat, 2007-08-25 at 21:12 +0200, Turbo Fredriksson wrote: Quoting Phil Mayers [EMAIL PROTECTED]: 2) INNER Auth part ensures that the ldap module is only called for the INNER part of the check...not for everything else. also very very useful as it stops outer ID junk and debris from

Re: access only particular website through RADIUS

2007-08-26 Thread Nick Owen
On 8/26/07, Arran Cudbard-Bell [EMAIL PROTECTED] wrote: liran tal wrote: Others may correct me but I believe that this is not the role of the RADIUS server. To actually do this kind of filtering you need to use other technologies such as proxies or captive portal (see chillispot). Yep

Re: 13 LDAP queries for one authorize!

2007-08-26 Thread Alan DeKok
Phil Mayers wrote: I'm only slightly wiser from reading that... Shouldn't 'eap' and 'mschap' be in this Authz-Type to then? No I will note that in CVS head (2.0-pre2), this is *much* easier to understand. There's a configuration file for the outer tunnel piece, and a separate one for the

Re: Freeradius, Cisco WLC, Mac address auth.

2007-08-26 Thread Alan DeKok
Brian Ertel wrote: I have freeradius working with a Cisco 2000 series controller. A wireless client attempts to associate with a WAP the controller sends an auth request to freeradius who sees the mac address of the user: 00:0e:35:1c:e0:52 Auth-Type := Local, User-Password == testing